Ir al contenido

Roles & permissions

Esta página aún no está disponible en tu idioma.

Who can do what, and why you may not see a screen that this documentation describes.

AuthPlus separates the people who check items from the people who manage them. Only the latter have accounts.

Verifier — no account
Anyone using the verification app. Identified by a verifier profile on their device rather than by a login. Ordinary customers get one automatically; trade and inspection profiles are issued with a username and password. A verifier can scan, view the verdict, transfer custody and see the history of their own scans. They have no access to the dashboard.
Standard user — the default account
A brand owner. Sees and manages only what they own: their brands, products, assets, contents, items, issuances, codes and verifiers, plus the operations and warnings those generate. This is the role every self-registered account receives.
Administrator
Everything a standard user can do, but across all owners, plus user management, global settings, the prohibited-name blocklist, brand-badge approvals and the full warning queue.
Superadministrator
A single platform-operator account created when the server is first started. Adds the platform-wide catalogue — code types, print templates and verifier types — and maintenance actions. It is never listed in Users and cannot be modified by administrators.

full access   limited — see note   no access

CapabilityVerifierStandardAdminSuper
Verify codes, files and links
Transfer custody of a code
Sign in to the dashboard
Create & manage brands, subjects, items, issuances, codes own any owner
Generate PDF / CSV label documents own
Create & manage verifier accounts permitted types only permitted types only all types
View operations (audit trail & map) own all
View warnings own over-verified only all kinds
Request a brand verification badge
Approve, reject or revoke a badge
Switch the owner filter (see other owners’ data)
Create users & change roles Standard/Admin only Standard/Admin only
Archive / restore a user account not self not self
Global settings (ceilings, label footer)
Prohibited-name blocklist
Code types, print templates, verifier types read-only read-only
Enable / disable interface languages

Two rules constrain administrators, by design:

  • You cannot change your own role or archive your own account. This prevents an administrator from accidentally locking everyone out of the platform. Ask another administrator.
  • The superadministrator is untouchable. It does not appear in the user list and cannot be demoted, archived, or created from the interface.

Every list in the dashboard is filtered by the owner scope in force. For a standard user that scope is fixed to their own account and cannot be changed. For an administrator it is chosen in the sidebar and applies everywhere at once — lists, statistics, the map, warnings and the global search. See §27 The owner filter.